{"id":"CVE-2017-1000001","details":"FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.","aliases":["GHSA-p7xc-35m8-57pr","PYSEC-2017-13"],"modified":"2026-07-08T10:54:17.685874Z","published":"2017-07-17T13:18:15.937Z","references":[{"type":"ADVISORY","url":"https://github.com/fedora-infra/fedmsg/blob/0.18.2/CHANGELOG.rst"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/fedora-infra/fedmsg","events":[{"introduced":"0"},{"last_affected":"c8c144dd9ae193957cfbb329d1af64d5bef14b8c"}],"database_specific":{"cpe":"cpe:2.3:a:fedoraproject:fedmsg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.18.1"}],"source":"CPE_RANGE"}}],"versions":["0.18.1","0.16.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-1000001.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}